Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideLink scanner evidence to a Risk, assess grouped technical vulnerabilities and preserve the evidence correctly across completed assessments and reassessments.
A scanner reports observations such as a Qualys QID on a host, port or service. PurpleWASP links selected observations to a business Risk and groups them by the technical vulnerability identity. This avoids creating hundreds of Risk records from one scan while keeping the evidence auditable.
Evidence can be linked from the Asset Vulnerabilities workspace or from Identification & Analysis → Technical Exposure in the Risk assessment. Use the link-state filter to distinguish Linked, Not linked and Partially linked groups.
Manual Weaknesses / Vulnerabilities / Causes remain available for non-scanner conditions such as weak process, governance or organisational controls.
For each linked group, record the factors used by the qualitative Identification scenario:
A group is assessed once even when several findings, ports or services belong to the same source vulnerability.
Open Details to review the provider title/description, CVEs where mapped, remediation guidance, affected service/port, observation dates, occurrence count, scanner evidence and status history. This evidence is supporting context; the assessor still owns the business-scenario judgement.
When a qualitative assessment is completed, PurpleWASP freezes the linked technical vulnerabilities and their exploitability, control-effectiveness and uncertainty values into that assessment version. Later provider changes do not rewrite the completed assessment evidence.
Confirm you are in the live reassessment version rather than viewing a completed historical assessment. The current reassessment should show live linked evidence.
Keep the link when it remains relevant to assessment history. Resolution changes the current technical posture but does not erase the evidence or automatically close the Risk.
Use the grouped view. PurpleWASP assesses the technical vulnerability once while retaining the individual observations underneath it.